Skip to content
Solvex Space

Cybersecurity · free, no signup

Attack Surface Mapper

Every certificate you are issued publishes its hostnames to a permanent public log, so an attacker starts with your inventory rather than having to find it. This reads that same log and triages it: hostnames delegating to a third-party service that no longer exists — the subdomain takeover shape, where whoever registers the released name next serves content on your domain, inside your cookies, with a valid certificate — plus administrative, build-system and pre-production hosts that were never meant to be public, and private addresses leaked into public DNS. Entirely passive: no port is scanned, no hostname is guessed, no host is connected to, and a takeover is reported but never attempted.

Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.

Reads the hostnames your domain has published to the public Certificate Transparency logs and triages them: which names point at a service that no longer exists and could be claimed by someone else, which ones name systems that were never meant to be public, and what the naming gives away about the estate.

Entirely passive. No port is scanned, no hostname is guessed, and nothing connects to the hosts it finds — the inputs are a public append-only log and ordinary DNS answers. Certificates, DNS and email posture for the domain itself belong to the OSINT Exposure Scanner and are not repeated here.

Use a domain you own or are authorized to assess.

What happens to what you enter

  • The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
  • Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
  • An email address is stored only where a tool offers to send you a report and you choose to give one.

Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.

When a free check is not enough

This tool reads what is public and reports what it can see. The External Network Penetration Testing engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.

Explore External Network Penetration Testing
Attack Surface Mapper — Solvex Space